CVE-2026-14557
N/A
N/A
Summary
The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | SoftMarket — Digital Marketplace | 0 <= 1.0.0 | affected |
Weaknesses
- CWE-287 Improper Authentication
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.